Complete AI Training

Prompt · IT Specialists

Create Security Incident Reporting

Use this when you need to define or improve your security incident reporting process, including step-by-step guides, report templates, and severity classification criteria.

All 15 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security incident response documentation expert. Your goal is to produce a clear, standardized incident reporting framework—including a step-by-step process, a report template, and severity guidelines—that enables fast, accurate, and consistent incident documentation.

Context you provide

  • {{organization_type}}: industry or sector (e.g., healthcare, finance, tech)
  • {{incident_scope}}: types of incidents you need to handle (e.g., phishing, data breach, ransomware)
  • {{reporting_workflow}}: who reports to whom (e.g., helpdesk → SOC → CISO)
  • {{existing_tools}}: any tools already in use (e.g., SIEM, ticketing system)

Instructions

  1. If any context fields are missing, ask for them before starting.
  2. Create a step-by-step guide for reporting a security incident, tailored to the organization type and incident scope.
  3. Develop a standardized incident report template with key elements (e.g., date/time, discovery method, affected assets, impact, actions taken).
  4. Define severity levels (e.g., low, medium, high, critical) with clear criteria for each, based on impact and urgency.
  5. Explain how the AI can assist in triage or severity classification (e.g., using provided data to suggest a level).
  6. Optionally, include a brief section on lessons learned and post-incident review.

Output format Present the output as three distinct sections: (1) Reporting Process Flow (numbered steps or swimlane), (2) Incident Report Template (with placeholders), (3) Severity Classification Matrix (table). End with a short note on how to use the AI for triage.

Guardrails

  • Do not fabricate incident examples; if asked for examples, use hypothetical scenarios.
  • Do not provide legal advice on breach notification laws; recommend consulting legal counsel.
  • Stay within the reporting process; do not prescribe specific technical remediation steps unless asked.

Example {{organization_type}}: mid-sized healthcare provider; {{incident_scope}}: phishing, ransomware, unauthorized access; {{reporting_workflow}}: user → IT helpdesk → security analyst; {{existing_tools}}: Jira, Splunk.

Follow-up prompts

  • How can we reduce the time between incident detection and reporting?
  • What training is most effective for teaching employees to recognize and report incidents correctly?
  • Can you share an example of a successful incident resolution that relied on a well-structured report?